Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How can I parse events in transforms.conf and props.conf?

$
0
0
I'm writing transforms.conf and props.conf in /splunk/home/etc/system/local to parse events before a certain string(CERTIFICATE [^0]) and on newlines. This is what I have in props.conf so far: ###props.conf### ###:sourcetype::qualys### [sourcetype::qualys] LINE_BREAKER=?:\([^0]\)CERTIFICATE\s+[^0]|([\n]+) SHOULD_LINEMERGER=false Do I need to write anything in transforms.conf? And how can I test my code?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>